Illinois Governor Signs Landmark AI Act With First-in-Nation Mandatory Third-Party Audit for Frontier Models
Illinois has enacted the Artificial Intelligence Safety Measures Act, becoming the first U.S. state to mandate annual independent third-party audits for developers of massive frontier AI models. The legislation joins similar frameworks in California and New York to solidify a de facto national standard for AI safety and transparency.
By Logan Price
- State Regulators
- Argue that states must lead on AI safety to protect the public amid federal inaction.
- Legal & Compliance Experts
- Focus on the operational impact of the law and the emergence of a de facto national standard.
- Consumer Advocates
- Praise the transparency measures but criticize the inability of individuals to sue for AI-driven harms.
Why this matters
By mandating independent safety audits for the world's most powerful AI systems, Illinois is closing a major loophole in tech oversight. Because the law applies to any major developer doing business in the state, it effectively forces national compliance, giving the public unprecedented visibility into the risks of frontier models.
Key points
- Illinois is the first U.S. state to mandate independent third-party safety audits for large AI developers.
- The law applies only to frontier models trained with massive computing power by companies earning over $500 million annually.
- Developers must report critical safety incidents to state emergency agencies within 24 to 72 hours.
- The legislation relies on the state Attorney General for enforcement, with fines reaching up to $3 million for repeat offenses.
- Combined with similar laws in California and New York, the act helps establish a de facto national standard for AI safety.
Illinois Governor JB Pritzker has signed the Artificial Intelligence Safety Measures Act (SB 315) into law, establishing one of the most stringent regulatory frameworks for advanced AI in the United States. The legislation makes Illinois the first state to require mandatory, independent third-party audits for developers of massive "frontier" AI models. [1][3][1][3]
The new law targets the largest and most resource-intensive artificial intelligence systems—specifically those trained using more than 10²⁶ floating-point operations by companies generating over $500 million in annual revenue. [6][7] By setting these high thresholds, the legislation focuses squarely on industry giants like OpenAI, Google, Anthropic, and Meta, rather than stifling smaller startups or open-source researchers. [4][6][4][6]
The centerpiece of the legislation is its unprecedented audit mandate. Beginning in 2028, large frontier developers must hire independent third-party evaluators to annually assess their compliance with safety protocols and internal risk controls. [6][8] Crucially, the law stipulates strict independence criteria, ensuring that auditors have no financial conflicts of interest with the tech companies they are evaluating. [8][6][7]

Beyond audits, the law requires developers to publish comprehensive safety frameworks detailing how they identify and mitigate "catastrophic risks"—such as the potential for an AI model to assist in creating biological weapons or executing large-scale cyberattacks. [1][7] Companies must also report critical safety incidents to the Illinois Emergency Management Agency and Office of Homeland Security within 72 hours, or just 24 hours if the risk is deemed imminent. [5][6][1][5][6]
Enforcement of the new regulations falls exclusively to the Illinois Attorney General, who can levy civil penalties of up to $1 million for a first violation and $3 million for subsequent offenses. [3][8] The legislation does not include a private right of action, meaning individual citizens cannot sue AI companies directly under this specific law for algorithmic harms, a compromise that helped secure broad bipartisan support. [4][5][3][4][5][7]
During the signing ceremony in Chicago, Governor Pritzker framed the legislation as a necessary intervention in the face of federal gridlock. He emphasized that the state is choosing a path of "innovation with security," ensuring that the costs and detriments of unchecked technological growth are not pushed onto ordinary citizens. [1][3] Pritzker openly criticized Congress for remaining captive to special interests and failing to pass a cohesive national framework. [1][2][1][2][3]
During the signing ceremony in Chicago, Governor Pritzker framed the legislation as a necessary intervention in the face of federal gridlock.
Illinois now joins California and New York, which passed similar frontier AI transparency laws in late 2025. [1][2] Legal experts note that because these three states collectively account for roughly 40% of the U.S. AI market, their combined regulations effectively create a de facto national standard. [1][6] It is logistically unfeasible for major tech companies to build separate AI models for different states, meaning the Illinois audit requirement will likely become standard industry practice nationwide. [6][8][1][2][6][7]

The tech industry's reaction has been surprisingly cooperative. Major players like OpenAI have publicly endorsed the Illinois framework, describing it as one of the strongest safety laws in the country. [6] This support reflects a growing consensus among leading labs that clear, predictable state regulations are preferable to a chaotic patchwork of conflicting local ordinances or the looming threat of more draconian federal interventions. [6][7][6]
The transparency and reporting provisions of the Artificial Intelligence Safety Measures Act will officially take effect on January 1, 2027, giving developers a brief runway to align their internal compliance programs. [6][8] The more rigorous third-party audit requirements will follow a year later in 2028, marking a critical transition from an era of self-reported AI safety to one of verified, independent oversight. [7][8][6][7]
How we got here
Late 2025
California and New York pass the nation's first major frontier AI transparency laws.
May 2026
The Illinois General Assembly passes the Artificial Intelligence Safety Measures Act (SB 315) with bipartisan support.
July 2026
Governor JB Pritzker signs the bill into law, adding the first-in-the-nation third-party audit requirement.
January 2027
Transparency, reporting, and safety framework requirements officially take effect.
January 2028
Mandatory independent third-party audits begin for all qualifying large frontier developers.
Viewpoints in depth
State Regulators & Lawmakers
State governments are stepping in to fill the regulatory void left by federal inaction.
Lawmakers in Illinois, California, and New York argue that waiting for Congress to pass comprehensive AI legislation is no longer a viable strategy. By implementing strict transparency and audit requirements at the state level, they aim to establish a baseline of accountability before frontier models become deeply entrenched in critical infrastructure. They view these laws not as anti-innovation, but as necessary guardrails that protect the public from catastrophic risks while providing clear rules of the road for developers.
Frontier AI Developers
Leading AI companies are embracing state-level frameworks to ensure regulatory predictability.
Major developers like OpenAI and Anthropic have largely supported these state-level transparency bills. For the industry's biggest players, complying with mandatory audits and safety frameworks is a manageable cost of doing business that helps build public trust. Furthermore, a unified bloc of state laws is vastly preferable to a fragmented landscape of conflicting local rules. By endorsing bills like the Illinois Act, these companies can help shape the regulatory environment and avoid more restrictive measures that might stifle core research.
Consumer Rights Advocates
While praising the safety audits, advocates warn that the lack of a private right of action limits direct accountability.
Consumer protection groups celebrate the mandatory third-party audits as a historic win for algorithmic transparency. However, they express concern over the law's enforcement mechanism, which relies entirely on the state Attorney General. Because the legislation explicitly excludes a private right of action, individuals who are harmed by an AI system—such as through algorithmic discrimination in hiring or healthcare—cannot use this specific law to sue the developers directly. Advocates argue this leaves a critical gap in compensating victims of AI-driven harm.
What we don't know
- How the independent third-party auditing industry will scale to meet the complex technical demands of evaluating frontier AI models by 2028.
- Whether the federal government will eventually preempt these state-level frameworks with a unified national AI law.
- Exactly how 'catastrophic risk' thresholds will be legally defined and measured in practice during the auditing process.
Key terms
- Frontier Model
- A highly capable foundation AI model trained using massive amounts of computing power, typically exceeding 10²⁶ floating-point operations.
- Third-Party Audit
- An independent evaluation conducted by an external organization to verify that a company is complying with safety and regulatory standards.
- Private Right of Action
- A legal provision that allows ordinary citizens to file lawsuits directly against a company for violating a specific law.
- Catastrophic Risk
- The potential for an AI system to cause large-scale harm, such as assisting in the creation of biological weapons or facilitating severe cyberattacks.
Frequently asked
Does this law apply to all AI startups?
No. The law specifically targets 'large frontier developers' with over $500 million in annual revenue that train models using massive computing power. Small startups and open-source researchers are generally exempt.
Can I sue an AI company under this new law?
No. The legislation does not include a private right of action. Only the Illinois Attorney General has the authority to enforce the law and levy fines against violators.
When do the new rules take effect?
The transparency and safety reporting requirements begin on January 1, 2027. The mandatory third-party audits will start a year later, on January 1, 2028.
Sources
[1]Capitol News IllinoisState Regulators
Pritzker signs landmark AI regulation bill that aims to mitigate risks
Read on Capitol News Illinois →[2]The Washington PostState Regulators
Gov. JB Pritzker has signed a new artificial intelligence law in Illinois
Read on The Washington Post →[3]JURISTState Regulators
Illinois Governor JB Pritzker signs landmark artificial intelligence bill
Read on JURIST →[4]The Legal ExaminerConsumer Advocates
What Does the Illinois Artificial Intelligence Safety Measures Act Do?
Read on The Legal Examiner →[5]Transparency CoalitionConsumer Advocates
Illinois Gov. Pritzker signs nation's 'most protective' AI Safety Measures Act into law
Read on Transparency Coalition →[6]SkaddenLegal & Compliance Experts
Illinois Imposes Transparency and Safety Obligations on Frontier AI Systems
Read on Skadden →[7]Latham & WatkinsLegal & Compliance Experts
Illinois' SB 315 is the first law in the US to mandate third-party audits for large AI developers
Read on Latham & Watkins →
Every angle. Every day.
Get ai stories with full source coverage and perspective breakdowns delivered to your inbox.








